#StopRansomware: Ghost (Cring) Ransomware


The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint advisory to disseminate known Ghost (Cring)— (“Ghost”)—ransomware IOCs and TTPs identified through FBI investigation as recently as January 2025. Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions of software and firmware.

This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China. Ghost actors, located in China, conduct these widespread attacks for financial gain. Affected victims include critical infrastructure, schools and universities, healthcare, government networks, religious institutions, technology and manufacturing companies, and numerous small- and medium-sized businesses.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • DHS: Secretary Mayorkas Designates Ukraine for Temporary Protected Status for 18 Months

    March 2, 2022

    WASHINGTON — The Department of Homeland Security (DHS) announced the designation of Ukraine for Temporary Protected Status (TPS) for 18 months. “Russia’s premeditated and unprovoked attack on Ukraine has resulted in an ongoing war, senseless violence, and Ukrainians forced to seek refuge in other countries,” said Secretary Alejandro N. Mayorkas. “In these extraordinary times, we will ...

  • Quarter of a million lawyer disciplinary records leak

    February 28, 2022

    Approximately 260,000 nonpublic disciplinary records stored on behalf of The State Bar of California were found to be exposed to the public and to have been republished on Judyrecords.com, a website that aggregates over 630 million public court records. The sensitive records exposed include the case number, filing date, case type, case status, and respondent and ...

  • The United Kingdom Is Prepared for NATO-Russia Cyber Conflict

    February 27, 2022

    The unfolding Ukraine crisis has focused attention on the role of cyber operations in defensive and offensive military-intelligence strategy. Russia’s cyber aggression against Ukrainian government and civilian targets was expected and is consistent with its long-standing information war strategy and conduct across its “near abroad.” What is less certain is how Western powers should respond ...

  • White House denies reports that it is considering cyberattacks on Russian infrastructure

    February 24, 2022

    The White House has denied reports that it is considering a range of cyberattacks on Russian infrastructure in response to the invasion of Ukraine. The denials came after NBC News reported US President Joe Biden was offered options that included the use of American cyberweapons “on a scale never before contemplated.” Reporters for NBC News claimed they ...

  • US to attack cyber criminals first, ask questions later – if it protects victims

    February 21, 2022

    The United States Department of Justice (DoJ) has revealed new policies that may see it undertake pre-emptive action against cyber threats. Revealed last week by deputy attorney general Lisa O. Monaco, in a speech at the Munich Cyber Security Conference, the policy will see prosecutors, agents and analysts assess “whether to use disruptive actions against cyber ...

  • CISA Insights: Foreign Influence Operations Targeting Critical Infrastructure

    February 18, 2022

    CISA has released CISA Insights: Preparing for and Mitigating Foreign Influence Operations Targeting Critical Infrastructure, which provides proactive steps organizations can take to assess and mitigate risks from information manipulation. Malicious actors may use tactics—such as misinformation, disinformation, and malinformation—to shape public opinion, undermine trust, and amplify division, which can lead to impacts to critical ...